
Your data is in Europe. Who can access it?
The US CLOUD Act, a Dutch warning and the plain questions every organisation should be asking its cloud provider.
Where data sits and who can compel it aren't the same question.
Where your data is stored and who has legal control over it aren't the same thing. Most of the current noise about digital sovereignty comes down to that one idea, and the law usually at the centre of it is the US CLOUD Act. This post covers what the Act does and doesn't do, what actually happened in the Netherlands this spring, and what an organisation can do now.
What the CLOUD Act actually says
The US Congress passed the Clarifying Lawful Overseas Use of Data Act in March 2018, as part of a large spending bill. Its core provision is a single sentence (18 U.S.C. § 2713). It says a provider of communication or cloud services must preserve or disclose data "within such provider's possession, custody, or control, regardless of whether" that data sits inside or outside the United States. [Law]
In plain terms, if a provider is subject to US jurisdiction and receives a valid US order, keeping the data in Dublin, Frankfurt or Manchester doesn't, on its own, put it out of reach. The limits matter too:
- It needs lawful process. The Act works through existing US criminal procedure. For the content of emails or files, that normally means a warrant approved by a judge, not an informal request. [Law]
- Providers can push back. There's a formal challenge where disclosure would break the law of a country with a US agreement, and other objections remain possible. Microsoft says it contractually commits to resist unfounded requests. [Law; vendor claim]
- The secrecy comes from elsewhere. Orders that stop a provider telling a customer come from an older provision (18 U.S.C. § 2705(b)), not the CLOUD Act itself. For the customer, the effect can be the same. [Law]
- It isn't the only route. Intelligence surveillance runs under separate law (notably FISA section 702), and Congress has its own subpoena powers, as the Dutch case shows.
The Act also allows "executive agreements" letting trusted countries serve orders directly on each other's providers in serious crime cases. The UK has had one since October 2022. EU–US talks began in 2019; participants in recent Atlantic Council workshops described them as frozen. [Government statement; policy research]
So the honest summary is neither "the US can take anything" nor "it's a myth". A US-controlled provider can be compelled, you may not be told, and server location doesn't settle it. In June 2025 a Microsoft France executive, asked under oath by a French Senate inquiry whether he could guarantee French data would never reach US authorities without French consent, said he couldn't, adding that it had never happened. [Press report]
What happened in the Netherlands
In late May 2026, the Dutch magazine Vrij Nederland reported that names of Dutch civil servants had turned up in material Microsoft handed to the US House of Representatives Judiciary Committee. The committee is investigating what it calls European "censorship" under the Digital Services Act. [Press report]
Here's what is documented:
- Who: staff at the competition authority (ACM) and data protection authority (AP), both involved in enforcing the Act, plus at least one disinformation researcher. [Press reports]
- What: emails, meeting minutes and invitations with names left in. A Dutch government briefing says ACM names later appeared in the committee's report and appendices. [Press reports; government document]
- How: subpoenas the committee issued to ten tech companies for their communications with European regulators. No report I've seen describes it as a CLOUD Act order. NOS reported that, as far as is known, the material came from Microsoft's own business systems, not systems it runs for the Dutch government; Microsoft said it concerned correspondence with Microsoft itself, not customers' mail. [Press reports; committee letters; vendor statement]
- Response: the cabinet called it "extremely concerning" and raised it with the US ambassador. On 23 June State Secretary Eric van der Burg told parliament he would ask Microsoft, Meta and the US embassy what was shared, how often and under which law; the AP had put questions to Microsoft; and ACM and AP now use generic mailboxes. A follow-up letter was promised; I haven't found it published yet. [Government statement]
Early coverage mentioned a Senate committee and named Meta too; a June government briefing said no evidence had yet been found of Meta passing on personal data. Details may still change. It wasn't a CLOUD Act case, but it shows the principle: a US company, under US legal compulsion, handed over material exposing European officials, and their government learned of it from the press.
It isn't just a government problem
Most organisations will never interest a congressional committee. But the question applies to a housing association, a law firm or a 20-person engineering firm in Stockport: whose legal system ultimately governs the company holding your email, files and backups? UK organisations are in the same position as EU ones. Being outside the EU doesn't change a US provider's jurisdiction, and the UK–US agreement adds a route for serious crime cases rather than removing one.
What "sovereign cloud" offers do and don't solve
Every major hyperscaler now sells some kind of "sovereign" or "EU boundary" offer. Microsoft, for example, says it completed its EU Data Boundary in February 2025, keeping most customer data storage and processing within the EU and EFTA. [Vendor claim]
These can help with residency, access control and audit. Treat them as vendor claims to question, not answers: residency isn't jurisdiction. If the parent company is subject to US law, ask what would technically and contractually stop it complying with an order, and who controls those measures.
Whoever holds the keys holds the control.

Questions to ask now
You don't need a strategy to start, just honest answers to five questions:
- Who has legal control of the provider? Not where the data centre is, but which company, in which country, can be compelled.
- Where are the encryption keys, and who holds them? Provider-held keys protect against theft, not against a lawful order to the provider. Customer-held keys change that, at a cost in complexity.
- Can we get our data out, in usable formats, within a reasonable time? Test it rather than assume it.
- What's our plan B? If a service became unavailable or unacceptable tomorrow, what would you switch to, and how fast?
- Which data actually matters? Classify first, then decide what belongs where.
The wider picture
There is real activity in Europe, though it's easy to overstate. Germany's openDesk and France's La Suite numérique are open-source public-sector workplace suites that share some components. On 3 June 2026 the European Commission proposed a Chips Act 2.0 to reduce dependence in chip design and manufacturing; it's a proposal, not yet law. None is a drop-in hyperscaler replacement today, but they're options that weren't credible a few years ago.
Sovereignty is a set of choices, not a single switch.

The point
The CLOUD Act isn't new, and it isn't secret. What has changed is the political climate in which it, and powers like it, might be used. The Dutch case is a reminder that jurisdiction follows the company, not the cable. Sovereignty isn't an on/off switch; it's a set of choices about control, keys and exits. The useful first step is to know where you stand, and to have a plan B you've actually tested.
Sources
- Tweede Kamer: GroenLinks-PvdA asks about tech companies sharing civil servants' names (question time, 26 May 2026)
- NOS: Tech companies shared names of Dutch civil servants with the US (22 May 2026, in Dutch)
- Dutch government letter to parliament on protecting civil servants' personal data (23 June 2026, in Dutch)
- Binnenlands Bestuur: Microsoft shared names of Dutch civil servants with a US House committee (22 May 2026, in Dutch)
- Politico Europe: US committee demands Big Tech share private communications with EU officials (March 2026)
- US House Judiciary Committee letter to Microsoft about its subpoena (16 March 2026, PDF)
- 18 U.S.C. § 2713: the CLOUD Act's core disclosure provision (Cornell LII)
- 18 U.S.C. § 2703, including the § 2703(h) comity challenge (Cornell LII)
- 18 U.S.C. § 2705: delayed notice and non-disclosure orders (Cornell LII)
- US Department of Justice: CLOUD Act resources
- Congressional Research Service: Cross-Border Data Sharing Under the CLOUD Act
- UK Government: UK–US Data Access Agreement text, in force 3 October 2022 (PDF)
- Atlantic Council DFRLab: Sovereignty without borders, on the transatlantic digital relationship (August 2026)
- The Register: Microsoft admits it "cannot guarantee" data sovereignty (July 2025)
- Microsoft: EU Data Boundary completion announcement (February 2025, vendor source)
- European Commission: Proposal for the Chips Act 2.0 (3 June 2026)
- openDesk: open-source workplace suite for the public sector (Germany)
- La Suite numérique: open-source tools for the French public sector
This is general commentary, not legal advice. Claims are labelled by type: law, government statement, press report or vendor claim.

Drafted with assistant help; Mark Braddock owns the published wording. SovereignBase · Manchester, UK.
